echo.defender 0 Report post Posted July 1, 2006 Invision Power Board v2.1.6 ? 2006 IPS, Inc. This is what it is written on the bottom of the board. Not so long ago, i was surfing somewhere, (i wont say where) and i discovered a "sql injection"exploit, a perl script. 28. Reload and click on the username to the admin. You are now logged in as an ADMIN!!! Admins, pm to receive the link where i found this. with this hack, you can log in with any user without his pass. It's really easy to do, you just need PERL, Opera webbrowser and 3 minutes fo your life... Share this post Link to post Share on other sites
Albus Dumbledore 0 Report post Posted July 1, 2006 this is why IPB has recently sent out a new update for this version of 2.1.6http://forums.xisto.com/no_longer_exists/is the update in which they are talkng aboutand here is another IPB Error that was released yesterday... which people need to upgrade onhttp://forums.xisto.com/no_longer_exists/it talks about uploading avatars that will cause cross site scripting... Share this post Link to post Share on other sites
echo.defender 0 Report post Posted July 1, 2006 this is why IPB has recently sent out a new update for this version of 2.1.6http://forums.xisto.com/no_longer_exists/is the update in which they are talkng aboutand here is another IPB Error that was released yesterday... which people need to upgrade onhttp://forums.xisto.com/no_longer_exists/it talks about uploading avatars that will cause cross site scripting... Yay a good administrator in a forum! thats rare! lol Share this post Link to post Share on other sites
delivi 0 Report post Posted July 1, 2006 Thanks dude this would have become a serious proble for the forumers. This will alert all th forum admins here and they'll definetly update. If any one of you've been attacked with this exploit then, report it here. Share this post Link to post Share on other sites
echo.defender 0 Report post Posted July 2, 2006 Thanks dude this would have become a serious proble for the forumers. This will alert all th forum admins here and they'll definetly update. If any one of you've been attacked with this exploit then, report it here. i did my good action of the day lol Share this post Link to post Share on other sites
uiop 0 Report post Posted July 2, 2006 Security exploits like this make me nervous. I used to run an old version of IPB (I only purchased one year or so of updates), but decided to quit using it because of all the new security vulnrabilities.Are these forums updated? Share this post Link to post Share on other sites
echo.defender 0 Report post Posted July 2, 2006 this is why IPB has recently sent out a new update for this version of 2.1.6http://forums.xisto.com/no_longer_exists/is the update in which they are talkng aboutand here is another IPB Error that was released yesterday... which people need to upgrade onhttp://forums.xisto.com/no_longer_exists/it talks about uploading avatars that will cause cross site scripting... Share this post Link to post Share on other sites